CVE-2021-28918

9.1
CRITICALCVSS v3.1 Base Score
16.66%
LOW RiskEPSS (97th percentile)

Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.

Published: 4/1/2021
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS v2 Score

6.4

AV:N/AC:L/Au:N/C:P/I:P/A:N

EPSS Score (Exploitation Probability)

16.66%LOW Exploitation Risk
97th percentile

This vulnerability has a 16.66% probability of being exploited in the next 30 days, ranking higher than 97% of all scored CVEs.

CWE Classification

Advertisement